Package Health

abmmhasan/safeguard

MIT licensing is clear, releases are frequent, and the source project has tests and a security policy. Its low popularity provides little independent evidence for a security-focused dependency.

Latest 3.1PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo package mentiondanger

The repository name does not match the package name and its README does not mention the package. Together with the README describing Epicrypt, this makes the repository linkage and package provenance unclear.

Package scaffoldingcaution

The artifact includes a substantial README, while the repository has tests; the missing artifact changelog and tests are normal packaging choices. However, the README describes a different project, which weakens its consumer documentation value.

Project backingcaution

The linked repository is owned by an organization, which provides some continuity and handoff capacity. That support does not resolve the package-to-repository identity mismatch.

Repo bus factorcaution

One contributor made all 353 commits in the last three months, leaving no demonstrated backup maintainer. Organization ownership offers some handoff capacity, but no second active contributor is shown.

Workflow auditcaution

The audit covered both workflows with no untrusted checkout, injection, or high-confidence findings, and permissions are scoped or read-only. However, all 18 action references are unpinned, leaving workflow dependencies exposed to moving upstream code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Infocyph
abmmhasan

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/simple-cache
Version ^3.0
—
—
phpseclib/phpseclib
Version ^4.0.1
—
—

Weekly Downloads

Info

Last Published
15 days ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform